Zurück   Trojaner-Board > Malware entfernen > Plagegeister aller Art und deren Bekämpfung

Plagegeister aller Art und deren Bekämpfung: immer wieder neue Setup.exe in Temp-Ordner

Windows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen.

 
Alt 22.12.2013, 23:22   #1
fundiko
 
immer wieder neue Setup.exe in Temp-Ordner - Standard

immer wieder neue Setup.exe in Temp-Ordner



Hallo zusammen,

Ich habe seit ein paar Tagen immer wieder eine merkwürdige Setup.exe in meinem Temp-Ordner.
Aus dem Nichts heraus kommt dann jedesmal die Abfrage, ob ich die Installation zulassen will oder nicht.
Natürlich klick ich dann immer auf Nein.

CCleaner und Spybot hab ich schon etliche Male gestartet. Bringt aber nichts. Das letzte mal hat sich die Setup.exe auf meinem Laptop gemeldet, unmittelbar, nachdem ich CCleaner und Spybot laufen lassen hab.

Wie in der Anleitung beschrieben, hab ich alle Scans ausgeführt und poste sie hier wie folgt:

defogger_disable.log :

defogger_disable by jpshortstuff (23.02.10.1)
Log created at 22:34 on 22/12/2013 (max)

Checking for autostart values...
HKCU\~\Run values retrieved.
HKLM\~\Run values retrieved.

Checking for services/drivers...


-=E.O.F=-

---------------------------------

Addition.txt :FRST Additions Logfile:
Code:
ATTFilter
Additional scan result of Farbar Recovery Scan Tool (x64) Version: 22-12-2013 01
Ran by max at 2013-12-22 22:37:23
Running from C:\Users\max\Downloads
Boot Mode: Normal
==========================================================


==================== Security Center ========================

AV: avast! Antivirus (Enabled - Up to date) {17AD7D40-BA12-9C46-7131-94903A54AD8B}
AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Spybot - Search and Destroy (Enabled - Out of date) {9BC38DF1-3CCA-732D-A930-C1CA5F20A4B0}
AS: avast! Antivirus (Enabled - Up to date) {ACCC9CA4-9C28-93C8-4B81-AFE241D3E736}

==================== Installed Programs ======================

7-Zip 9.20 (x64 edition) (Version: 9.20.00.0)
Adobe AIR (x32 Version: 3.8.0.1430)
Adobe Flash Player 11 ActiveX (x32 Version: 11.9.900.170)
Adobe Flash Player 11 Plugin (x32 Version: 11.9.900.170)
Adobe Reader XI (11.0.05) - Deutsch (x32 Version: 11.0.05)
Amazon Kindle (HKCU)
Apple Application Support (x32 Version: 2.3.4)
Apple Software Update (x32 Version: 2.1.3.127)
Ashampoo Burning Studio Elements 10.0.9 (x32 Version: 3.1.1)
Ask Toolbar (x32 Version: 12.9.1.17) <==== ATTENTION
avast! Free Antivirus (x32 Version: 9.0.2008)
Brother MFL-Pro Suite DCP-195C (x32 Version: 1.0.1.0)
calibre (x32 Version: 0.8.28)
Canon Utilities CameraWindow DC 8 (x32 Version: 8.9.0.4)
Canon Utilities Digital Photo Professional (x32 Version: 3.12.20.0)
Canon Utilities ImageBrowser EX (x32 Version: 1.2.1.13)
Canon Utilities PhotoStitch (x32 Version: 3.1.23.47)
CCleaner (Version: 4.08)
CDex - Open Source Digital Audio CD Extractor (x32 Version: 1.70.4.2009)
Celestia 1.6.0 (x32)
Compatibility Pack für 2007 Office System (x32 Version: 12.0.6612.1000)
Exif-Viewer 2.50  (x32 Version: 2.50)
Explorer Suite III
FileParade Bundle (x32 Version: 1.0.0.0)
GIMP 2.8.4 (Version: 2.8.4)
Google Chrome (x32 Version: 31.0.1650.63)
Google Earth (x32 Version: 7.1.1.1888)
Google Update Helper (x32 Version: 1.3.22.3)
Image Resizer Powertoy Clone for Windows (64 bit) (Version: 2.1.1)
Java 7 Update 45 (x32 Version: 7.0.450)
Java Auto Updater (x32 Version: 2.1.9.8)
K-Lite Codec Pack 7.6.0 (Full) (x32 Version: 7.6.0)
MainConcept MJPEG Codec Demo (x32 Version: 3.02.0004.0000)
MainConcept MJPG software codec (Remove Only) (x32)
McAfee Security Scan Plus (Version: 3.8.130.10)
MediaInfo 0.7.61 (Version: 0.7.61)
Microsoft .NET Framework 4 Client Profile (Version: 4.0.30319)
Microsoft Application Error Reporting (Version: 12.0.6015.5000)
Microsoft Office Excel MUI (German) 2007 (x32 Version: 12.0.6612.1000)
Microsoft Office File Validation Add-In (x32 Version: 14.0.5130.5003)
Microsoft Office Home and Student 2007 (x32 Version: 12.0.6612.1000)
Microsoft Office Office 64-bit Components 2007 (Version: 12.0.6612.1000)
Microsoft Office OneNote MUI (German) 2007 (x32 Version: 12.0.6612.1000)
Microsoft Office PowerPoint MUI (German) 2007 (x32 Version: 12.0.6612.1000)
Microsoft Office PowerPoint Viewer 2007 (German) (x32 Version: 12.0.6612.1000)
Microsoft Office Proof (English) 2007 (x32 Version: 12.0.6612.1000)
Microsoft Office Proof (French) 2007 (x32 Version: 12.0.6612.1000)
Microsoft Office Proof (German) 2007 (x32 Version: 12.0.6612.1000)
Microsoft Office Proof (Italian) 2007 (x32 Version: 12.0.6612.1000)
Microsoft Office Shared 64-bit MUI (German) 2007 (Version: 12.0.6612.1000)
Microsoft Office Shared MUI (German) 2007 (x32 Version: 12.0.6612.1000)
Microsoft Office Word MUI (German) 2007 (x32 Version: 12.0.6612.1000)
Microsoft Silverlight (Version: 5.1.20913.0)
Microsoft SQL Server Compact 3.5 SP2 ENU (x32 Version: 3.5.8080.0)
Microsoft SQL Server Compact 3.5 SP2 x64 ENU (Version: 3.5.8080.0)
Microsoft Visual C++ 2005 ATL Update kb973923 - x64 8.0.50727.4053 (Version: 8.0.50727.4053)
Microsoft Visual C++ 2005 Redistributable (x32 Version: 8.0.56336)
Microsoft Visual C++ 2005 Redistributable (x32 Version: 8.0.59193)
Microsoft Visual C++ 2005 Redistributable (x32 Version: 8.0.61001)
Microsoft Visual C++ 2005 Redistributable (x64) (Version: 8.0.56336)
Microsoft Visual C++ 2005 Redistributable (x64) (Version: 8.0.61000)
Microsoft Visual C++ 2008 ATL Update kb973924 - x64 9.0.30729.4148 (Version: 9.0.30729.4148)
Microsoft Visual C++ 2008 Redistributable - KB2467174 - x64 9.0.30729.5570 (Version: 9.0.30729.5570)
Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570 (x32 Version: 9.0.30729.5570)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.21022 (Version: 9.0.21022)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (Version: 9.0.30729.6161)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30411 (x32 Version: 9.0.30411)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729 (x32 Version: 9.0.30729)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (x32 Version: 9.0.30729)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (x32)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (x32 Version: 9.0.30729.6161)
Microsoft Works (x32 Version: 9.7.0621)
Motorola Driver Installation 3.9.0 (Version: 3.9.0)
Movie Studio Platinum 12.0 (64-bit) (Version: 12.0.756)
Mozilla Firefox 26.0 (x86 de) (x32 Version: 26.0)
Mozilla Maintenance Service (x32 Version: 26.0)
Mozilla Thunderbird 24.2.0 (x86 de) (x32 Version: 24.2.0)
MSVCRT Redists (Version: 1.0)
MSVCRT Redists (x32 Version: 1.0)
MSXML 4.0 SP2 (KB954430) (x32 Version: 4.20.9870.0)
MSXML 4.0 SP2 (KB973688) (x32 Version: 4.20.9876.0)
MSXML 4.0 SP3 Parser (KB2758694) (x32 Version: 4.30.2117.0)
MSXML 4.0 SP3 Parser (x32 Version: 4.30.2100.0)
NTRIP (x32)
NVIDIA Drivers (Version: 1.4)
OpenOffice.org 3.4 (x32 Version: 3.4.9590)
Paint.NET v3.5.10 (Version: 3.60.0)
PaperPort Image Printer 64-bit (Version: 1.00.0000)
PhotoScape (x32)
PL-2303 USB-to-Serial (x32 Version: 1.4.17)
Quick Media Converter Ask Toolbar Updater (HKCU Version: 1.2.0.20007) <==== ATTENTION
QuickTime (x32 Version: 7.74.80.86)
ScanSoft PaperPort 11 (x32 Version: 11.2.0000)
Silicon Laboratories CP210x USB to UART Bridge (Driver Removal) (x32)
Spybot - Search & Destroy (x32 Version: 2.0.12)
Synaptics Pointing Device Driver (Version: 14.0.10.0)
TomTom HOME (x32 Version: 2.9.6)
TomTom HOME Visual Studio Merge Modules (x32)
Überwachungstool für die Intel® Turbo-Boost-Technik (Version: 1.0.186.3)
Update for Microsoft .NET Framework 4 Client Profile (KB2468871) (x32 Version: 1)
Update for Microsoft .NET Framework 4 Client Profile (KB2533523) (x32 Version: 1)
Update for Microsoft .NET Framework 4 Client Profile (KB2600217) (x32 Version: 1)
Update for Microsoft .NET Framework 4 Client Profile (KB2836939) (x32 Version: 1)
Update for Microsoft .NET Framework 4 Client Profile (KB2836939v3) (x32 Version: 3)
Update miniHomer 2.8 Version 2.8 (x32 Version: 2.8)
Update miniHomer Version 2.6 (x32 Version: 2.6)
Updater (x32 Version: 2.6.49)
VIS (x32)
VLC media player 2.1.0 (x32 Version: 2.1.0)
VSO Image Resizer 4.0.2.5 (x32 Version: 4.0.2.5)
Websteroids (x32 Version: 2.6.49)
WIDCOMM Bluetooth Software (Version: 6.2.1.800)
Windows Driver Package - Broadcom Bluetooth  (07/30/2009 6.2.0.9405) (Version: 07/30/2009 6.2.0.9405)
Windows Driver Package - Broadcom Bluetooth  (09/11/2009 6.2.0.9407) (Version: 09/11/2009 6.2.0.9407)
Windows Driver Package - Broadcom HIDClass  (07/28/2009 6.2.0.9800) (Version: 07/28/2009 6.2.0.9800)
Windows Internet Explorer 10 (x32 Version: 10.0)
Windows Live Family Safety (Version: 14.0.8118.427)
Windows Live ID-Anmelde-Assistent (Version: 6.500.3165.0)
WinRAR 5.00 (64-bit) (Version: 5.00.0)
XMedia Recode 3.0.6.0 (x32 Version: 3.0.6.0)

==================== Restore Points  =========================


==================== Hosts content: ==========================

2009-07-14 03:34 - 2009-06-10 22:00 - 00000824 ___AC C:\windows\system32\Drivers\etc\hosts

==================== Scheduled Tasks (whitelisted) =============

Task: {253AA94C-B81C-4ABE-957C-FAD1ACB9967E} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [2011-06-01] (Apple Inc.)
Task: {30A8F779-13BB-4F05-9A52-0787653C4CDA} - System32\Tasks\SamsungSupportCenter => C:\Program Files (x86)\Samsung\Samsung Support Center\SSCKbdHk.exe [2009-12-14] (SAMSUNG Electronics)
Task: {34B2FBD7-7971-44BB-8127-8664E93256E0} - System32\Tasks\avast! Emergency Update => C:\Program Files\Alwil Software\Avast5\AvastEmUpdate.exe [2013-12-13] (AVAST Software)
Task: {5A8D4D33-F9F7-49FA-90F6-3A0D6EDFCE6F} - System32\Tasks\EasySpeedUpManager => C:\Program Files (x86)\Samsung\EasySpeedUpManager\EasySpeedUpManager.exe [2009-10-13] (Samsung Electronics Co., Ltd.)
Task: {5BDCE4B0-9980-4211-828F-D2D7C61775AD} - System32\Tasks\EasyDisplayMgr => C:\Program Files (x86)\Samsung\Easy Display Manager\dmhkcore.exe [2009-11-04] (Samsung Electronics Co., Ltd.)
Task: {5C466351-1661-4AC2-A8CC-C5B327D34C8C} - System32\Tasks\Safer-Networking\Spybot - Search and Destroy\Scan the system => C:\Program Files (x86)\Spybot - Search &amp; Destroy 2\SDScan.exe
Task: {5DEA853F-7A4D-43E8-9449-FE0E57B034BD} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2013-12-10] (Adobe Systems Incorporated)
Task: {76044278-48D0-41B5-B1A8-93832FCCDF2C} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2011-07-23] (Google Inc.)
Task: {7DF9C0E6-37F4-43E2-A928-39BDAA0648AB} - System32\Tasks\EasyBatteryManager => C:\Program Files (x86)\Samsung\EasyBatteryManager\EasyBatteryMgr4.exe [2009-10-16] (SAMSUNG Electronics co., LTD.)
Task: {83558952-CA50-4A20-A13A-3EC5D8E21A8D} - System32\Tasks\BatteryLifeExtender => C:\Program Files (x86)\Samsung\BatteryLifeExtender\BatteryLifeExtender.exe [2009-11-19] (Samsung Electronics. Co. Ltd.)
Task: {9887809C-EA83-4BF8-8BB3-701D5D708A8F} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2011-07-23] (Google Inc.)
Task: {9E2BC02C-B839-49C0-82AA-FE85FB334095} - System32\Tasks\Safer-Networking\Spybot - Search and Destroy\Refresh immunization => C:\Program Files (x86)\Spybot - Search &amp; Destroy 2\SDImmunize.exe
Task: {9F05B2AF-D111-4F97-88E5-0B2E112469F4} - System32\Tasks\Safer-Networking\Spybot - Search and Destroy\Check for updates => C:\Program Files (x86)\Spybot - Search &amp; Destroy 2\SDUpdate.exe
Task: {B17A6072-0100-4950-A768-0A6F8177F7C2} - System32\Tasks\Microsoft\Windows\WindowsBackup\AutomaticBackup => Rundll32.exe /d sdengin2.dll,ExecuteScheduledBackup
Task: {B5AA7C9B-E68D-4359-AA63-B2ED2557B0FE} - System32\Tasks\SUPBackground => C:\Program Files\Samsung\Samsung Update Plus\SUPBackground.exe
Task: {C135D8E8-FC1A-4546-B2C0-59F4F79A83E2} - System32\Tasks\advSRS4 => C:\Program Files (x86)\Samsung\Samsung Recovery Solution 4\WCScheduler.exe [2010-01-19] (SEC)
Task: {CA283BEE-3EC0-466E-A81A-EB392CBC959D} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2013-11-22] (Piriform Ltd)
Task: {CEC26ED2-C2FA-4BA9-8C61-07CCAA3AE285} - System32\Tasks\APSchedulerC => C:\Program Files (x86)\AnyPC Client\APLanMgrC.exe [2009-11-20] (DoctorSoft)
Task: C:\windows\Tasks\Adobe Flash Player Updater.job => C:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe

==================== Loaded Modules (whitelisted) =============

2013-12-22 22:09 - 2013-12-22 17:58 - 02154496 _____ () C:\Program Files\Alwil Software\Avast5\defs\13122201\algo.dll
2010-02-09 07:08 - 2006-08-12 04:48 - 00049152 _____ () C:\Program Files (x86)\Samsung\Easy Display Manager\HookDllPS2.dll
2013-04-09 15:13 - 2012-11-13 13:06 - 00108960 _____ () C:\Program Files (x86)\Spybot - Search & Destroy 2\snlThirdParty150.bpl
2013-04-09 15:13 - 2012-11-13 13:06 - 00416160 _____ () C:\Program Files (x86)\Spybot - Search & Destroy 2\DEC150.bpl
2013-04-09 15:13 - 2012-11-13 13:06 - 00158624 _____ () C:\Program Files (x86)\Spybot - Search & Destroy 2\snlFileFormats150.bpl
2013-04-09 15:13 - 2012-08-23 08:38 - 00574840 _____ () C:\Program Files (x86)\Spybot - Search & Destroy 2\sqlite3.dll
2013-04-09 15:13 - 2012-11-13 13:06 - 00528288 _____ () C:\Program Files (x86)\Spybot - Search & Destroy 2\JSDialogPack150.bpl
2013-05-01 11:48 - 2013-01-29 18:45 - 00112128 ____C () C:\Program Files (x86)\Canon\ImageBrowser EX\MFMFileSystemWatcher.dll
2009-06-03 12:59 - 2009-06-03 12:59 - 00619816 ____N () C:\Program Files (x86)\CyberLink\Power2Go\CLMediaLibrary.dll
2009-06-03 12:59 - 2009-06-03 12:59 - 00013096 ____N () C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvcPS.dll
2012-04-13 11:04 - 2012-04-13 11:04 - 00985088 _____ () C:\Program Files (x86)\OpenOffice.org 3\program\libxml2.dll
2012-04-13 11:00 - 2012-04-13 11:00 - 00170496 _____ () C:\Program Files (x86)\OpenOffice.org 3\program\libxslt.dll
2010-11-20 13:15 - 2009-02-27 16:38 - 00139264 ____R () C:\Program Files (x86)\Brother\BrUtilities\BrLogAPI.dll
2013-04-09 15:13 - 2012-11-13 13:06 - 00554400 _____ () C:\Program Files (x86)\Spybot - Search & Destroy 2\VirtualTreesDXE150.bpl
2013-12-13 21:11 - 2013-12-13 21:11 - 19336120 _____ () C:\Program Files\Alwil Software\Avast5\libcef.dll
2002-07-27 23:53 - 2002-07-27 23:53 - 00040960 _____ () C:\Program Files (x86)\Winamp\Plugins\in_cdda.dll
2002-08-20 20:01 - 2002-08-20 20:01 - 00134656 _____ () C:\Program Files (x86)\Winamp\Plugins\in_mp3.dll
2002-08-02 00:26 - 2002-08-02 00:26 - 00035328 _____ () C:\Program Files (x86)\Winamp\Plugins\in_wave.dll
2001-12-30 16:08 - 2001-12-30 16:08 - 00015360 _____ () C:\Program Files (x86)\Winamp\Plugins\out_disk.dll
2002-08-20 21:56 - 2002-08-20 21:56 - 00041984 _____ () C:\Program Files (x86)\Winamp\Plugins\out_ds.dll
2002-07-23 19:38 - 2002-07-23 19:38 - 00013824 _____ () C:\Program Files (x86)\Winamp\Plugins\out_wave.dll
2013-12-20 14:17 - 2013-12-20 14:18 - 03559024 ____C () C:\Program Files (x86)\Mozilla Firefox\mozjs.dll

==================== Alternate Data Streams (whitelisted) =========

AlternateDataStreams: C:\ProgramData\Temp:AD022376

==================== Safe Mode (whitelisted) ===================

HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MCODS => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MpfService => ""="Service"

==================== Faulty Device Manager Devices =============

Name: Broadcom BCM2070 Bluetooth 2.1+EDR USB Device
Description: Broadcom BCM2070 Bluetooth 2.1+EDR USB Device
Class Guid: {e0cbf06c-cd8b-4647-bb8a-263b43f0f974}
Manufacturer: Broadcom
Service: BTHUSB
Problem: : This device is disabled. (Code 22)
Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions.


==================== Event log errors: =========================

Application errors:
==================
Error: (12/22/2013 07:00:00 PM) (Source: Windows Backup) (User: )
Description: Die Sicherung wurde aufgrund eines Fehlers beim Schreiben am Sicherungsspeicherort "I:\" nicht abgeschlossen. Fehler: "Der Sicherungsort wurde nicht gefunden oder ist ungültig. Überprüfen Sie die Sicherungseinstellungen und den Sicherungsort. (0x81000006)"

Error: (12/22/2013 10:05:28 AM) (Source: SideBySide) (User: )
Description: Fehler beim Generieren des Aktivierungskontextes für "WLMFDS,processorArchitecture="AMD64",type="win32",version="1.0.0.1"1". Fehler in Manifest- oder Richtliniendatei "WLMFDS,processorArchitecture="AMD64",type="win32",version="1.0.0.1"2" in Zeile  WLMFDS,processorArchitecture="AMD64",type="win32",version="1.0.0.1"3.
Die im Manifest gefundene Komponenten-ID stimmt nicht mit der ID der angeforderten Komponente überein.
Verweis: WLMFDS,processorArchitecture="AMD64",type="win32",version="1.0.0.1".
Definition: WLMFDS,processorArchitecture="x86",type="win32",version="1.0.0.1".
Verwenden Sie das Programm "sxstrace.exe" für eine detaillierte Diagnose.

Error: (12/22/2013 10:04:53 AM) (Source: SideBySide) (User: )
Description: Fehler beim Generieren des Aktivierungskontextes für "WLMFDS,processorArchitecture="AMD64",type="win32",version="1.0.0.1"1". Fehler in Manifest- oder Richtliniendatei "WLMFDS,processorArchitecture="AMD64",type="win32",version="1.0.0.1"2" in Zeile  WLMFDS,processorArchitecture="AMD64",type="win32",version="1.0.0.1"3.
Die im Manifest gefundene Komponenten-ID stimmt nicht mit der ID der angeforderten Komponente überein.
Verweis: WLMFDS,processorArchitecture="AMD64",type="win32",version="1.0.0.1".
Definition: WLMFDS,processorArchitecture="x86",type="win32",version="1.0.0.1".
Verwenden Sie das Programm "sxstrace.exe" für eine detaillierte Diagnose.

Error: (12/21/2013 03:46:29 PM) (Source: SideBySide) (User: )
Description: Fehler beim Generieren des Aktivierungskontextes für "WLMFDS,processorArchitecture="AMD64",type="win32",version="1.0.0.1"1". Fehler in Manifest- oder Richtliniendatei "WLMFDS,processorArchitecture="AMD64",type="win32",version="1.0.0.1"2" in Zeile  WLMFDS,processorArchitecture="AMD64",type="win32",version="1.0.0.1"3.
Die im Manifest gefundene Komponenten-ID stimmt nicht mit der ID der angeforderten Komponente überein.
Verweis: WLMFDS,processorArchitecture="AMD64",type="win32",version="1.0.0.1".
Definition: WLMFDS,processorArchitecture="x86",type="win32",version="1.0.0.1".
Verwenden Sie das Programm "sxstrace.exe" für eine detaillierte Diagnose.

Error: (12/21/2013 03:45:34 PM) (Source: SideBySide) (User: )
Description: Fehler beim Generieren des Aktivierungskontextes für "WLMFDS,processorArchitecture="AMD64",type="win32",version="1.0.0.1"1". Fehler in Manifest- oder Richtliniendatei "WLMFDS,processorArchitecture="AMD64",type="win32",version="1.0.0.1"2" in Zeile  WLMFDS,processorArchitecture="AMD64",type="win32",version="1.0.0.1"3.
Die im Manifest gefundene Komponenten-ID stimmt nicht mit der ID der angeforderten Komponente überein.
Verweis: WLMFDS,processorArchitecture="AMD64",type="win32",version="1.0.0.1".
Definition: WLMFDS,processorArchitecture="x86",type="win32",version="1.0.0.1".
Verwenden Sie das Programm "sxstrace.exe" für eine detaillierte Diagnose.

Error: (12/21/2013 09:21:01 AM) (Source: SideBySide) (User: )
Description: Fehler beim Generieren des Aktivierungskontextes für "WLMFDS,processorArchitecture="AMD64",type="win32",version="1.0.0.1"1". Fehler in Manifest- oder Richtliniendatei "WLMFDS,processorArchitecture="AMD64",type="win32",version="1.0.0.1"2" in Zeile  WLMFDS,processorArchitecture="AMD64",type="win32",version="1.0.0.1"3.
Die im Manifest gefundene Komponenten-ID stimmt nicht mit der ID der angeforderten Komponente überein.
Verweis: WLMFDS,processorArchitecture="AMD64",type="win32",version="1.0.0.1".
Definition: WLMFDS,processorArchitecture="x86",type="win32",version="1.0.0.1".
Verwenden Sie das Programm "sxstrace.exe" für eine detaillierte Diagnose.

Error: (12/21/2013 09:20:21 AM) (Source: SideBySide) (User: )
Description: Fehler beim Generieren des Aktivierungskontextes für "WLMFDS,processorArchitecture="AMD64",type="win32",version="1.0.0.1"1". Fehler in Manifest- oder Richtliniendatei "WLMFDS,processorArchitecture="AMD64",type="win32",version="1.0.0.1"2" in Zeile  WLMFDS,processorArchitecture="AMD64",type="win32",version="1.0.0.1"3.
Die im Manifest gefundene Komponenten-ID stimmt nicht mit der ID der angeforderten Komponente überein.
Verweis: WLMFDS,processorArchitecture="AMD64",type="win32",version="1.0.0.1".
Definition: WLMFDS,processorArchitecture="x86",type="win32",version="1.0.0.1".
Verwenden Sie das Programm "sxstrace.exe" für eine detaillierte Diagnose.

Error: (12/21/2013 09:20:20 AM) (Source: Windows Search Service) (User: )
Description: Der Index kann nicht initialisiert werden.


Details:
	Der Inhaltsindexkatalog ist fehlerhaft.  (HRESULT : 0xc0041801) (0xc0041801)

Error: (12/21/2013 09:20:20 AM) (Source: Windows Search Service) (User: )
Description: Die Anwendung kann nicht initialisiert werden.

Kontext: Windows Anwendung


Details:
	Der Inhaltsindexkatalog ist fehlerhaft.  (HRESULT : 0xc0041801) (0xc0041801)

Error: (12/21/2013 09:20:20 AM) (Source: Windows Search Service) (User: )
Description: Das Gatherer-Objekt kann nicht initialisiert werden.

Kontext: Windows Anwendung, SystemIndex Katalog


Details:
	Der Inhaltsindexkatalog ist fehlerhaft.  (HRESULT : 0xc0041801) (0xc0041801)


System errors:
=============
Error: (12/22/2013 06:27:01 PM) (Source: volsnap) (User: )
Description: Die Schattenkopien von Volume "C:" wurden abgebrochen, weil der Schattenkopiespeicher nicht auf ein benutzerdefiniertes Limit vergrößert werden konnte.

Error: (12/21/2013 04:05:02 PM) (Source: Disk) (User: )
Description: Der Treiber hat einen Controllerfehler auf \Device\Harddisk1\DR5 gefunden.

Error: (12/21/2013 03:58:22 PM) (Source: Disk) (User: )
Description: Der Treiber hat einen Controllerfehler auf \Device\Harddisk1\DR2 gefunden.

Error: (12/21/2013 03:58:20 PM) (Source: Disk) (User: )
Description: Der Treiber hat einen Controllerfehler auf \Device\Harddisk1\DR2 gefunden.

Error: (12/21/2013 03:58:19 PM) (Source: Disk) (User: )
Description: Der Treiber hat einen Controllerfehler auf \Device\Harddisk1\DR2 gefunden.

Error: (12/21/2013 03:58:17 PM) (Source: Disk) (User: )
Description: Der Treiber hat einen Controllerfehler auf \Device\Harddisk1\DR2 gefunden.

Error: (12/21/2013 03:58:15 PM) (Source: Disk) (User: )
Description: Der Treiber hat einen Controllerfehler auf \Device\Harddisk1\DR2 gefunden.

Error: (12/21/2013 03:58:13 PM) (Source: Disk) (User: )
Description: Der Treiber hat einen Controllerfehler auf \Device\Harddisk1\DR2 gefunden.

Error: (12/21/2013 03:58:12 PM) (Source: Disk) (User: )
Description: Der Treiber hat einen Controllerfehler auf \Device\Harddisk1\DR2 gefunden.

Error: (12/21/2013 03:58:10 PM) (Source: Disk) (User: )
Description: Der Treiber hat einen Controllerfehler auf \Device\Harddisk1\DR2 gefunden.


Microsoft Office Sessions:
=========================
Error: (06/16/2012 08:29:52 AM) (Source: Microsoft Office 12 Sessions)(User: )
Description: ID: 1, Application Name: Microsoft Office Excel, Application Version: 12.0.6661.5000, Microsoft Office Version: 12.0.6612.1000. This session lasted 176 seconds with 0 seconds of active time.  This session ended with a crash.


==================== Memory info =========================== 

Percentage of memory in use: 65%
Total physical RAM: 3949.63 MB
Available physical RAM: 1374.9 MB
Total Pagefile: 7897.43 MB
Available Pagefile: 5263.48 MB
Total Virtual: 8192 MB
Available Virtual: 8191.8 MB

==================== Drives ================================

Drive c: (Lokal) (Fixed) (Total:79.62 GB) (Free:37.04 GB) NTFS
Drive d: (Volume) (Fixed) (Total:331.98 GB) (Free:165.92 GB) NTFS
Drive g: (Volume) (Fixed) (Total:39.06 GB) (Free:38.92 GB) NTFS
Drive i: () (Removable) (Total:15.12 GB) (Free:2.97 GB) FAT32

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (Size: 466 GB) (Disk ID: 2C06486A)
Partition 1: (Not Active) - (Size=993 KB) - (Type=42)
Partition 2: (Not Active) - (Size=15 GB) - (Type=27)
Partition 3: (Active) - (Size=100 MB) - (Type=42)
Partition 4: (Not Active) - (Size=80 GB) - (Type=42)

========================================================
Disk: 1 (Size: 15 GB) (Disk ID: 00000000)
Partition 1: (Not Active) - (Size=15 GB) - (Type=0C)

==================== End Of Log ============================
         
--- --- ---
FRST.txt :
FRST Logfile:

FRST Logfile:

FRST Logfile:
Code:
ATTFilter
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 22-12-2013 01
Ran by max (administrator) on MAX-PC on 22-12-2013 22:36:40
Running from C:\Users\max\Downloads
Windows 7 Home Premium Service Pack 1 (X64) OS Language: German Standard
Internet Explorer Version 11
Boot Mode: Normal

==================== Processes (Whitelisted) =================

(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(AVAST Software) C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
(SAMSUNG Electronics) C:\Program Files (x86)\Samsung\Samsung Support Center\SSCKbdHk.exe
(Samsung Electronics Co., Ltd.) C:\Program Files (x86)\Samsung\EasySpeedUpManager\EasySpeedUpManager.exe
(SEC) C:\Program Files (x86)\Samsung\Samsung Recovery Solution 4\WCScheduler.exe
(Samsung Electronics Co., Ltd.) C:\Program Files (x86)\Samsung\Easy Display Manager\dmhkcore.exe
(APN LLC.) C:\Program Files (x86)\AskPartnerNetwork\Toolbar\apnmcp.exe
(Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe
() C:\Windows\SysWOW64\Rezip.exe
(Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe
(TomTom) C:\Program Files (x86)\TomTom HOME 2\TomTomHOMEService.exe
(Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
(Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe
(Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Updater) C:\ProgramData\Updater\updater.exe
(Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
() C:\Program Files (x86)\Canon\ImageBrowser EX\MFManager.exe
(McAfee, Inc.) C:\Program Files\McAfee Security Scan\3.8.130\SSScheduler.exe
(CyberLink) C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(Cyberlink Corp.) C:\Program Files (x86)\CyberLink\PowerDVD8\PDVD8Serv.exe
(OpenOffice.org) C:\Program Files (x86)\OpenOffice.org 3\program\soffice.exe
(Nuance Communications, Inc.) C:\Program Files (x86)\ScanSoft\PaperPort\pptd40nt.exe
(OpenOffice.org) C:\Program Files (x86)\OpenOffice.org 3\program\soffice.bin
(WatchDog) C:\ProgramData\RHelpers\ChromeHelper\ChromeHelper.exe
(Brother Industries, Ltd.) C:\Program Files (x86)\Brother\Brmfcmon\BrMfcWnd.exe
(Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe
(Brother Industries, Ltd.) C:\Program Files (x86)\Brother\ControlCenter3\BrccMCtl.exe
(Brother Industries, Ltd.) C:\Program Files (x86)\Brother\Brmfcmon\BrMfcMon.exe
(WatchDog) C:\ProgramData\RHelpers\FirefoxHelper\FirefoxHelper.exe
(WatchDog) C:\ProgramData\RHelpers\IeHelper\IeHelper.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(APN) C:\Program Files (x86)\AskPartnerNetwork\Toolbar\Updater\TBNotifier.exe
(AVAST Software) C:\Program Files\Alwil Software\Avast5\AvastUI.exe
(Nullsoft) C:\Program Files (x86)\Winamp\winamp.exe
(Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdate.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
() C:\Users\max\Downloads\Defogger.exe

==================== Registry (Whitelisted) ==================

HKLM\...\Run: [RtHDVCpl] - C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [9644576 2009-12-15] (Realtek Semiconductor)
HKLM\...\Run: [SynTPEnh] - C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [1861416 2009-10-10] (Synaptics Incorporated)
HKLM\...\Run: [NvCplDaemon] - RUNDLL32.EXE C:\windows\system32\NvCpl.dll,NvStartup
HKCU\...\Run: [Spybot-S&D Cleaning] - C:\Program Files (x86)\Spybot - Search & Destroy 2\SDCleaner.exe [3713032 2012-11-13] (Safer-Networking Ltd.)
HKCU\...\Run: [Updater] - C:\ProgramData\Updater\updater.exe [481656 2013-11-20] (Updater)
MountPoints2: {b31c6295-adf7-11e0-9982-b482fe37fbac} - G:\iStudio.exe
HKLM-x32\...\Run: [UpdateLBPShortCut] - C:\Program Files (x86)\CyberLink\LabelPrint\MUITransfer\MUIStartMenu.exe [222504 2009-05-19] (CyberLink Corp.)
HKLM-x32\...\Run: [CLMLServer] - C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe [103720 2009-06-03] (CyberLink)
HKLM-x32\...\Run: [UpdateP2GoShortCut] - C:\Program Files (x86)\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe [222504 2009-05-19] (CyberLink Corp.)
HKLM-x32\...\Run: [UpdatePDRShortCut] - C:\Program Files (x86)\CyberLink\PowerDirector\MUITransfer\MUIStartMenu.exe [222504 2008-01-04] (CyberLink Corp.)
HKLM-x32\...\Run: [UpdatePPShortCut] - C:\Program Files (x86)\CyberLink\PowerProducer\MUITransfer\MUIStartMenu.exe [218408 2008-12-03] (CyberLink Corp.)
HKLM-x32\...\Run: [UpdatePSTShortCut] - C:\Program Files (x86)\CyberLink\DVD Suite\MUITransfer\MUIStartMenu.exe [210216 2009-07-21] (CyberLink Corp.)
HKLM-x32\...\Run: [APLangApp] - C:\Program Files (x86)\AnyPC Client\APLangApp.exe [13312 2009-11-20] (DoctorSoft)
HKLM-x32\...\Run: [UCam_Menu] - C:\Program Files (x86)\CyberLink\YouCam\MUITransfer\MUIStartMenu.exe [222504 2009-05-19] (CyberLink Corp.)
HKLM-x32\...\Run: [RemoteControl8] - C:\Program Files (x86)\CyberLink\PowerDVD8\PDVD8Serv.exe [83240 2008-03-20] (Cyberlink Corp.)
HKLM-x32\...\Run: [PDVD8LanguageShortcut] - C:\Program Files (x86)\CyberLink\PowerDVD8\Language\Language.exe [50472 2007-12-14] ()
HKLM-x32\...\Run: [SSBkgdUpdate] - C:\Program Files (x86)\Common Files\ScanSoft Shared\SSBkgdUpdate\SSBkgdUpdate.exe [210472 2006-10-25] (Nuance Communications, Inc.)
HKLM-x32\...\Run: [PaperPort PTD] - C:\Program Files (x86)\ScanSoft\PaperPort\pptd40nt.exe [29984 2008-07-09] (Nuance Communications, Inc.)
HKLM-x32\...\Run: [IndexSearch] - C:\Program Files (x86)\ScanSoft\PaperPort\IndexSearch.exe [46368 2008-07-09] (Nuance Communications, Inc.)
HKLM-x32\...\Run: [PPort11reminder] - C:\ProgramData\ScanSoft\PaperPort\11\Config\Ereg\Ereg.ini [344 2011-07-23] ()
HKLM-x32\...\Run: [BrMfcWnd] - C:\Program Files (x86)\Brother\Brmfcmon\BrMfcWnd.exe [1159168 2009-05-26] (Brother Industries, Ltd.)
HKLM-x32\...\Run: [ControlCenter3] - C:\Program Files (x86)\Brother\ControlCenter3\BrCtrCen.exe [114688 2008-12-24] (Brother Industries, Ltd.)
HKLM-x32\...\Run: [SDTray] - C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe [3825176 2012-11-13] (Safer-Networking Ltd.)
HKLM-x32\...\Run: [Adobe ARM] - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-04-04] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [APSDaemon] - C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [59720 2013-04-21] (Apple Inc.)
HKLM-x32\...\Run: [QuickTime Task] - C:\Program Files (x86)\QuickTime\QTTask.exe [421888 2013-05-01] (Apple Inc.)
HKLM-x32\...\Run: [SunJavaUpdateSched] - C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation)
HKLM-x32\...\Run: [ApnTBMon] - C:\Program Files (x86)\AskPartnerNetwork\Toolbar\Updater\TBNotifier.exe [1804240 2013-12-10] (APN)
HKLM-x32\...\Run: [20131121] - C:\Program Files\Alwil Software\Avast5\Setup\emupdate\4c881f8e-9c6b-4fc0-a442-f3667a52b239.exe [180184 2013-11-23] (AVAST Software)
HKLM-x32\...\Run: [Updater] - C:\ProgramData\Updater\updater.exe [481656 2013-11-20] (Updater)
HKLM-x32\...\Run: [AvastUI.exe] - C:\Program Files\Alwil Software\Avast5\AvastUI.exe [3568312 2013-12-13] (AVAST Software)
Startup: C:\Users\max\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.4.lnk
ShortcutTarget: OpenOffice.org 3.4.lnk -> C:\Program Files (x86)\OpenOffice.org 3\program\quickstart.exe ()
BootExecute: autocheck autochk * sdnclean64.exe

==================== Internet (Whitelisted) ====================

HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.yd.delta-search.com/?babsrc=HP_ss&mntrId=601EF67BCB2384C6&affID=119357&tt=040713_rdrctful&tsp=4937
HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://dsl-start.computerbild.de/?ie=10
HKCU\Software\Microsoft\Internet Explorer\Main,Secondary Start Pages = hxxp://dsl-start.computerbild.de/?ie=10
hxxp://mixidj.delta-search.com/?affID=121136&tt=190313_gr1&babsrc=HP_ss&mntrId=601EF67BCB2384C6
HKCU\Software\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = hxxp://dsl-start.computerbild.de/?ie=10
hxxp://mixidj.delta-search.com/?affID=121136&tt=190313_gr1&babsrc=HP_ss&mntrId=601EF67BCB2384C6
URLSearchHook: HKCU - (No Name) - {37483b40-c254-4a72-bda4-22ee90182c1e} - No File
URLSearchHook: HKCU - (No Name) - {a1e75a0e-4397-4ba8-bb50-e19fb66890f4} - No File
SearchScopes: HKLM-x32 - DefaultScope {AFDBDDAA-5D3F-42EE-B79C-185A7020515B} URL = hxxp://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT2475029
SearchScopes: HKLM-x32 - {AFDBDDAA-5D3F-42EE-B79C-185A7020515B} URL = hxxp://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT2475029
SearchScopes: HKCU - {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} URL = hxxp://www.yd.delta-search.com/?q={searchTerms}&babsrc=SP_ss&mntrId=601EF67BCB2384C6&affID=119357&tt=040713_rdrctful&tsp=4937
SearchScopes: HKCU - {171DEBEB-C3D4-40b7-AC73-056A5EBA4A7E} URL = hxxp://websearch.ask.com/redirect?client=ie&tb=CCS&o=15773&src=crm&q={searchTerms}&locale=en_US&apn_ptnrs=HN&apn_dtid=YYYYYYYYDE&apn_uid=162CDC29-8D1D-48C7-9F3D-B25C4FB776F5&apn_sauid=0BDC4AAB-D63A-4BF4-AB04-C7384DF02DB4
SearchScopes: HKCU - {4301F923-6526-4B7B-9074-BFFC22CC5836} URL = hxxp://www.computerbild.de/suche/index.html?s_text={searchTerms}
SearchScopes: HKCU - {67A2568C-7A0A-4EED-AECC-B5405DE63B64} URL = 
SearchScopes: HKCU - {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = 
SearchScopes: HKCU - {965CD262-60AA-4711-BCE6-2C3AC22DDA48} URL = hxxp://de.search.yahoo.com/search?p={searchTerms}
SearchScopes: HKCU - {AFDBDDAA-5D3F-42EE-B79C-185A7020515B} URL = hxxp://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT2475029
BHO: avast! Online Security - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\Alwil Software\Avast5\aswWebRepIE64.dll (AVAST Software)
BHO: Windows Live Family Safety Browser Helper Class - {4f3ed5cd-0726-42a9-87f5-d13f3d2976ac} - C:\Program Files\Windows Live\Family Safety\fssbho.dll (Microsoft Corporation)
BHO: Windows Live ID-Anmelde-Hilfsprogramm - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
BHO-x32: MSS+ Identifier - {0E8A89AD-95D7-40EB-8D9D-083EF7066A01} - C:\Program Files\McAfee Security Scan\3.8.130\McAfeeMSS_IE.dll (McAfee, Inc.)
BHO-x32: Websteroids - {44ed99e2-16a6-4b89-80d6-5b21cf42e78b} - C:\ProgramData\Websteroids\IE\common.dll (Creative Island Media, LLC)
BHO-x32: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files (x86)\Spybot - Search & Destroy 2\SDHelper.dll (Safer-Networking Ltd.)
BHO-x32: No Name - {5C255C8A-E604-49b4-9D64-90988571CECB} -  No File
BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\Alwil Software\Avast5\aswWebRepIE.dll (AVAST Software)
BHO-x32: Windows Live ID-Anmelde-Hilfsprogramm - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\microsoft shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Toolbar: HKLM - avast! Online Security - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\Alwil Software\Avast5\aswWebRepIE64.dll (AVAST Software)
Toolbar: HKLM-x32 - avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\Alwil Software\Avast5\aswWebRepIE.dll (AVAST Software)
Toolbar: HKCU - No Name - {37483B40-C254-4A72-BDA4-22EE90182C1E} -  No File
Toolbar: HKCU - No Name - {D4027C7F-154A-4066-A1AD-4243D8127440} -  No File
Handler-x32: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files (x86)\Windows Live\Messenger\msgrapp.14.0.8117.0416.dll (Microsoft Corporation)
Handler-x32: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files (x86)\Windows Live\Messenger\msgrapp.14.0.8117.0416.dll (Microsoft Corporation)
Tcpip\Parameters: [DhcpNameServer] 192.168.2.1

FireFox:
========
FF ProfilePath: C:\Users\max\AppData\Roaming\Mozilla\Firefox\Profiles\fo45zvps.default-1378284021730
FF NewTab: www.google.de
FF DefaultSearchEngine: Ask Search
FF SearchEngineOrder.1: Ask Search
FF SelectedSearchEngine: Ask Search
FF Homepage: www.google.de
FF Plugin: @adobe.com/FlashPlayer - C:\windows\system32\Macromed\Flash\NPSWF64_11_9_900_170.dll ()
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer - C:\windows\SysWOW64\Macromed\Flash\NPSWF32_11_9_900_170.dll ()
FF Plugin-x32: @canon.com/MycameraPlugin - C:\Program Files (x86)\Canon\MyCamera Download Plugin\NPCIG.dll (CANON INC.)
FF Plugin-x32: @Google.com/GoogleEarthPlugin - C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF Plugin-x32: @java.com/DTPlugin,version=10.45.2 - C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.45.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @mcafee.com/McAfeeMssPlugin - C:\Program Files\McAfee Security Scan\3.8.130\npMcAfeeMss.dll (McAfee, Inc.)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files (x86)\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/OfficeLive,version=1.5 - C:\Program Files (x86)\Microsoft\Office Live\npOLW.dll (Microsoft Corp.)
FF Plugin-x32: @microsoft.com/WLPG,version=14.0.8117.0416 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @videolan.org/vlc,version=1.0.5 - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=2.1.0 - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF SearchPlugin: C:\Users\max\AppData\Roaming\Mozilla\Firefox\Profiles\fo45zvps.default-1378284021730\searchplugins\ask-search.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml
FF Extension: vis - C:\Users\max\AppData\Roaming\Mozilla\Firefox\Profiles\fo45zvps.default-1378284021730\Extensions\EFGLQA@78ETGYN-0W7FN789T87.COM
FF Extension: Live Gold - C:\Users\max\AppData\Roaming\Mozilla\Firefox\Profiles\fo45zvps.default-1378284021730\Extensions\livegold@dotcreation
FF Extension: Websteroids - C:\Users\max\AppData\Roaming\Mozilla\Firefox\Profiles\fo45zvps.default-1378284021730\Extensions\support@websteroidsapp.com
FF Extension: DownloadHelper - C:\Users\max\AppData\Roaming\Mozilla\Firefox\Profiles\fo45zvps.default-1378284021730\Extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}
FF Extension: Exif Viewer - C:\Users\max\AppData\Roaming\Mozilla\Firefox\Profiles\fo45zvps.default-1378284021730\Extensions\exif_viewer@mozilla.doslash.org.xpi
FF Extension: Ask Toolbar - C:\Users\max\AppData\Roaming\Mozilla\Firefox\Profiles\fo45zvps.default-1378284021730\Extensions\toolbar_ORJ-V7@apn.ask.com.xpi
FF Extension: NoScript - C:\Users\max\AppData\Roaming\Mozilla\Firefox\Profiles\fo45zvps.default-1378284021730\Extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}.xpi
FF Extension: Adblock Plus - C:\Users\max\AppData\Roaming\Mozilla\Firefox\Profiles\fo45zvps.default-1378284021730\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi
FF Extension: BetterPrivacy - C:\Users\max\AppData\Roaming\Mozilla\Firefox\Profiles\fo45zvps.default-1378284021730\Extensions\{d40f5e7b-d2cf-4856-b441-cc613eeffbe3}.xpi
FF Extension: DownThemAll! - C:\Users\max\AppData\Roaming\Mozilla\Firefox\Profiles\fo45zvps.default-1378284021730\Extensions\{DDC359D1-844A-42a7-9AA1-88A850A938A8}.xpi
FF Extension: Menu Editor - C:\Users\max\AppData\Roaming\Mozilla\Firefox\Profiles\fo45zvps.default-1378284021730\Extensions\{EDA7B1D7-F793-4e03-B074-E6F303317FB0}.xpi
FF Extension: Java Console - C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0033-ABCDEFFEDCBA}
FF Extension: Java Console - C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0035-ABCDEFFEDCBA}
FF HKLM-x32\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\Alwil Software\Avast5\WebRep\FF
FF Extension: avast! Online Security - C:\Program Files\Alwil Software\Avast5\WebRep\FF
FF HKCU\...\Firefox\Extensions: [lwoofer@lyricswoofer.co] - C:\Program Files (x86)\LyricsWoofer\122.xpi
FF HKCU\...\Firefox\Extensions: [{5a95a9e0-59dd-4314-bd84-4d18ca83a0e2}] - C:\Program Files (x86)\Wajam\Firefox\{5a95a9e0-59dd-4314-bd84-4d18ca83a0e2}.xpi

Chrome: 
=======
CHR HomePage: hxxp://www.google.com
CHR RestoreOnStartup: "hxxp://www.google.com/"
CHR DefaultSearchKeyword: google.de
CHR DefaultSearchProvider: Google
CHR DefaultSearchURL: {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:originalQueryForSuggestion}{google:assistedQueryStats}{google:searchFieldtrialParameter}{google:searchClient}{google:sourceId}{google:instantExtendedEnabledParameter}{google:omniboxStartMarginParameter}ie={inputEncoding}
CHR Extension: (Google Docs) - C:\Users\max\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.5_0
CHR Extension: (Google Drive) - C:\Users\max\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.3_0
CHR Extension: (YouTube) - C:\Users\max\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.6_0
CHR Extension: (Google Search) - C:\Users\max\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.20_0
CHR Extension: (VIS) - C:\Users\max\AppData\Local\Google\Chrome\User Data\Default\Extensions\fmlgoencnlndpglbocajlimaikjohmab
CHR Extension: () - C:\Users\max\AppData\Local\Google\Chrome\User Data\Default\Extensions\igjjkeeamkpihpncmmbgdkhdnjpcfmfb\2.6.49_0
CHR Extension: (Speed Test Analysis) - C:\Users\max\AppData\Local\Google\Chrome\User Data\Default\Extensions\kckgnnipheglejoddfhekdjpbdbinhmb\1.0.0.5_0
CHR Extension: (Google Wallet) - C:\Users\max\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.5.0_0
CHR Extension: (Gmail) - C:\Users\max\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_1
CHR HKLM-x32\...\Chrome\Extension: [jnikkfemnfogahcandhlchoengjbeaij] - C:\Program Files (x86)\LyricsWoofer\122.crx
CHR HKLM-x32\...\Chrome\Extension: [kckgnnipheglejoddfhekdjpbdbinhmb] - C:\Users\max\AppData\Roaming\SpeedTestAnalysis\speedtestanalysis.crx
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION

==================== Services (Whitelisted) =================

R2 APNMCP; C:\Program Files (x86)\AskPartnerNetwork\Toolbar\apnmcp.exe [166352 2013-12-10] (APN LLC.)
R2 avast! Antivirus; C:\Program Files\Alwil Software\Avast5\AvastSvc.exe [50344 2013-12-13] (AVAST Software)
S3 McComponentHostService; C:\Program Files\McAfee Security Scan\3.8.130\McCHSvc.exe [288776 2013-09-06] (McAfee, Inc.)
R2 Rezip; C:\windows\SysWOW64\Rezip.exe [311296 2009-03-05] ()
R2 SDScannerService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe [1103392 2012-11-13] (Safer-Networking Ltd.)
R2 SDUpdateService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe [1369624 2012-11-13] (Safer-Networking Ltd.)
R2 SDWSCService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe [168384 2012-11-13] (Safer-Networking Ltd.)

==================== Drivers (Whitelisted) ====================

R2 aswFsBlk; C:\windows\system32\drivers\aswFsBlk.sys [38984 2013-12-13] (AVAST Software)
R2 aswMonFlt; C:\windows\system32\drivers\aswMonFlt.sys [84328 2013-12-13] (AVAST Software)
R1 aswRdr; C:\windows\system32\drivers\aswRdr2.sys [92544 2013-12-13] (AVAST Software)
R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [65776 2013-12-13] ()
R1 aswSnx; C:\windows\system32\drivers\aswSnx.sys [1032416 2013-12-13] (AVAST Software)
R1 aswSP; C:\windows\system32\drivers\aswSP.sys [409832 2013-12-13] (AVAST Software)
R1 aswTdi; C:\windows\system32\drivers\aswTdi.sys [65264 2013-12-13] (AVAST Software)
R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [205320 2013-12-13] ()
S3 s0017bus; C:\Windows\System32\DRIVERS\s0017bus.sys [116264 2008-05-27] (MCCI Corporation)
S3 s0017mdfl; C:\Windows\System32\DRIVERS\s0017mdfl.sys [19496 2008-05-27] (MCCI Corporation)
S3 s0017mdm; C:\Windows\System32\DRIVERS\s0017mdm.sys [159784 2008-05-27] (MCCI Corporation)
S3 s0017mgmt; C:\Windows\System32\DRIVERS\s0017mgmt.sys [138792 2008-05-27] (MCCI Corporation)
S3 s0017nd5; C:\Windows\System32\DRIVERS\s0017nd5.sys [34856 2008-05-27] (MCCI Corporation)
S3 s0017obex; C:\Windows\System32\DRIVERS\s0017obex.sys [137768 2008-05-27] (MCCI Corporation)
S3 s0017unic; C:\Windows\System32\DRIVERS\s0017unic.sys [153128 2008-05-27] (MCCI Corporation)
R3 seehcri; C:\Windows\System32\DRIVERS\seehcri.sys [34032 2008-01-09] (Sony Ericsson Mobile Communications)
R2 TurboB; C:\Windows\System32\DRIVERS\TurboB.sys [12728 2009-09-29] ()
R3 yukonw7; C:\Windows\System32\DRIVERS\yk62x64.sys [395264 2009-09-28] ()

==================== NetSvcs (Whitelisted) ===================


==================== One Month Created Files and Folders ========

2013-12-22 22:36 - 2013-12-22 22:37 - 00022702 ____C C:\Users\max\Downloads\FRST.txt
2013-12-22 22:36 - 2013-12-22 22:36 - 00000000 ___DC C:\FRST
2013-12-22 22:35 - 2013-12-22 22:35 - 01928280 ____C (Farbar) C:\Users\max\Downloads\FRST64.exe
2013-12-22 22:34 - 2013-12-22 22:34 - 00000468 ____C C:\Users\max\Downloads\defogger_disable.log
2013-12-22 22:34 - 2013-12-22 22:34 - 00000000 ____C C:\Users\max\defogger_reenable
2013-12-22 22:33 - 2013-12-22 22:33 - 00050477 ____C C:\Users\max\Downloads\Defogger.exe
2013-12-22 16:16 - 2013-12-22 16:16 - 04379048 ____C (Piriform Ltd) C:\Users\max\Downloads\ccsetup407.exe
2013-12-22 10:05 - 2013-12-22 10:05 - 00000000 __RDC C:\Users\max\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\CyberLink PowerDVD 8
2013-12-20 14:17 - 2013-12-20 14:18 - 00000000 ___DC C:\Program Files (x86)\Mozilla Firefox
2013-12-18 21:22 - 2013-12-18 21:22 - 00000664 ____C C:\Users\max\Desktop\Filme_Michael_Caine.txt
2013-12-15 13:03 - 2013-12-15 13:03 - 00368343 ____C C:\Users\max\AppData\Local\recently-used.xbel
2013-12-14 08:53 - 2013-12-14 08:53 - 00000000 ___DC C:\Users\max\AppData\Roaming\AVAST Software
2013-12-13 21:10 - 2013-12-13 21:10 - 00000000 ___DC C:\ProgramData\AVAST Software
2013-12-11 20:11 - 2013-12-11 20:11 - 14631424 _____ (Microsoft Corporation) C:\windows\system32\wmp.dll
2013-12-11 20:11 - 2013-12-11 20:11 - 12625920 _____ (Microsoft Corporation) C:\windows\system32\wmploc.DLL
2013-12-11 20:11 - 2013-12-11 20:11 - 12625408 _____ (Microsoft Corporation) C:\windows\SysWOW64\wmploc.DLL
2013-12-11 20:11 - 2013-12-11 20:11 - 11410432 _____ (Microsoft Corporation) C:\windows\SysWOW64\wmp.dll
2013-12-11 20:09 - 2013-12-11 20:09 - 23183360 _____ (Microsoft Corporation) C:\windows\system32\mshtml.dll
2013-12-11 20:09 - 2013-12-11 20:09 - 17112576 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtml.dll
2013-12-11 20:09 - 2013-12-11 20:09 - 12996608 _____ (Microsoft Corporation) C:\windows\system32\ieframe.dll
2013-12-11 20:09 - 2013-12-11 20:09 - 11221504 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieframe.dll
2013-12-11 20:09 - 2013-12-11 20:09 - 05769216 _____ (Microsoft Corporation) C:\windows\system32\jscript9.dll
2013-12-11 20:09 - 2013-12-11 20:09 - 04243968 _____ (Microsoft Corporation) C:\windows\SysWOW64\jscript9.dll
2013-12-11 20:09 - 2013-12-11 20:09 - 02764288 _____ (Microsoft Corporation) C:\windows\system32\iertutil.dll
2013-12-11 20:09 - 2013-12-11 20:09 - 02724864 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtml.tlb
2013-12-11 20:09 - 2013-12-11 20:09 - 02724864 _____ (Microsoft Corporation) C:\windows\system32\mshtml.tlb
2013-12-11 20:09 - 2013-12-11 20:09 - 02334208 _____ (Microsoft Corporation) C:\windows\system32\wininet.dll
2013-12-11 20:09 - 2013-12-11 20:09 - 02166784 _____ (Microsoft Corporation) C:\windows\SysWOW64\iertutil.dll
2013-12-11 20:09 - 2013-12-11 20:09 - 01995264 _____ (Microsoft Corporation) C:\windows\system32\inetcpl.cpl
2013-12-11 20:09 - 2013-12-11 20:09 - 01928192 _____ (Microsoft Corporation) C:\windows\SysWOW64\inetcpl.cpl
2013-12-11 20:09 - 2013-12-11 20:09 - 01820160 _____ (Microsoft Corporation) C:\windows\SysWOW64\wininet.dll
2013-12-11 20:09 - 2013-12-11 20:09 - 01395200 _____ (Microsoft Corporation) C:\windows\system32\urlmon.dll
2013-12-11 20:09 - 2013-12-11 20:09 - 01157632 _____ (Microsoft Corporation) C:\windows\SysWOW64\urlmon.dll
2013-12-11 20:09 - 2013-12-11 20:09 - 00817664 _____ (Microsoft Corporation) C:\windows\system32\ieapfltr.dll
2013-12-11 20:09 - 2013-12-11 20:09 - 00708608 _____ (Microsoft Corporation) C:\windows\system32\jscript9diag.dll
2013-12-11 20:09 - 2013-12-11 20:09 - 00703488 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieapfltr.dll
2013-12-11 20:09 - 2013-12-11 20:09 - 00574976 _____ (Microsoft Corporation) C:\windows\system32\ieui.dll
2013-12-11 20:09 - 2013-12-11 20:09 - 00553472 _____ (Microsoft Corporation) C:\windows\SysWOW64\jscript9diag.dll
2013-12-11 20:09 - 2013-12-11 20:09 - 00440832 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieui.dll
2013-12-11 20:09 - 2013-12-11 20:09 - 00218624 _____ (Microsoft Corporation) C:\windows\system32\ie4uinit.exe
2013-12-11 20:09 - 2013-12-11 20:09 - 00139264 _____ (Microsoft Corporation) C:\windows\system32\ieUnatt.exe
2013-12-11 20:09 - 2013-12-11 20:09 - 00111616 _____ (Microsoft Corporation) C:\windows\system32\ieetwcollector.exe
2013-12-11 20:09 - 2013-12-11 20:09 - 00066048 _____ (Microsoft Corporation) C:\windows\system32\iesetup.dll
2013-12-11 20:09 - 2013-12-11 20:09 - 00053760 _____ (Microsoft Corporation) C:\windows\system32\jsproxy.dll
2013-12-11 20:09 - 2013-12-11 20:09 - 00048640 _____ (Microsoft Corporation) C:\windows\system32\ieetwproxystub.dll
2013-12-11 20:09 - 2013-12-11 20:09 - 00043008 _____ (Microsoft Corporation) C:\windows\SysWOW64\jsproxy.dll
2013-12-11 20:09 - 2013-12-11 20:09 - 00033792 _____ (Microsoft Corporation) C:\windows\system32\iernonce.dll
2013-12-11 20:09 - 2013-12-11 20:09 - 00004096 _____ (Microsoft Corporation) C:\windows\system32\ieetwcollectorres.dll
2013-12-11 18:51 - 2013-12-12 08:12 - 00000000 ___DC C:\Program Files (x86)\Mozilla Thunderbird
2013-12-11 08:21 - 2013-12-11 08:21 - 00000000 ___DC C:\Users\max\Documents\PC Speed Maximizer
2013-12-11 08:16 - 2013-12-11 08:16 - 00002768 ____C C:\windows\System32\Tasks\CCleanerSkipUAC
2013-12-11 08:16 - 2013-12-11 08:16 - 00000827 ____C C:\Users\Public\Desktop\CCleaner.lnk
2013-12-11 08:16 - 2013-12-11 08:16 - 00000000 ___DC C:\Program Files\CCleaner
2013-12-11 08:15 - 2013-12-11 08:15 - 00000000 ___DC C:\ProgramData\Websteroids
2013-12-11 08:15 - 2013-12-11 08:15 - 00000000 ___DC C:\ProgramData\Updater
2013-12-11 08:15 - 2013-12-11 08:15 - 00000000 ___DC C:\ProgramData\RHelpers
2013-12-11 08:13 - 2013-12-11 08:13 - 01080504 ____C (Conduit) C:\Users\max\Downloads\CCleaner_TSV426SC.exe
2013-12-11 08:04 - 2013-12-11 20:10 - 03155968 _____ (Microsoft Corporation) C:\windows\system32\win32k.sys
2013-12-11 08:04 - 2013-12-11 20:10 - 00465920 _____ (Microsoft Corporation) C:\windows\system32\WMPhoto.dll
2013-12-11 08:04 - 2013-12-11 20:10 - 00417792 _____ (Microsoft Corporation) C:\windows\SysWOW64\WMPhoto.dll
2013-12-11 08:04 - 2013-12-11 20:10 - 00335360 _____ (Microsoft Corporation) C:\windows\system32\msieftp.dll
2013-12-11 08:04 - 2013-12-11 20:10 - 00301568 _____ (Microsoft Corporation) C:\windows\SysWOW64\msieftp.dll
2013-12-11 08:04 - 2013-12-11 20:09 - 00159232 _____ (Microsoft Corporation) C:\windows\SysWOW64\imagehlp.dll
2013-12-11 08:04 - 2013-12-11 20:09 - 00081408 _____ (Microsoft Corporation) C:\windows\system32\imagehlp.dll
2013-12-11 08:04 - 2013-12-11 20:09 - 00002048 _____ (Microsoft Corporation) C:\windows\SysWOW64\tzres.dll
2013-12-11 08:04 - 2013-12-11 20:09 - 00002048 _____ (Microsoft Corporation) C:\windows\system32\tzres.dll
2013-12-11 08:04 - 2013-12-11 20:08 - 00202752 _____ (Microsoft Corporation) C:\windows\system32\scrrun.dll
2013-12-11 08:04 - 2013-12-11 20:08 - 00168960 _____ (Microsoft Corporation) C:\windows\system32\wscript.exe
2013-12-11 08:04 - 2013-12-11 20:08 - 00163840 _____ (Microsoft Corporation) C:\windows\SysWOW64\scrrun.dll
2013-12-11 08:04 - 2013-12-11 20:08 - 00156160 _____ (Microsoft Corporation) C:\windows\system32\cscript.exe
2013-12-11 08:04 - 2013-12-11 20:08 - 00150016 _____ (Microsoft Corporation) C:\windows\system32\wshom.ocx
2013-12-11 08:04 - 2013-12-11 20:08 - 00141824 _____ (Microsoft Corporation) C:\windows\SysWOW64\wscript.exe
2013-12-11 08:04 - 2013-12-11 20:08 - 00126976 _____ (Microsoft Corporation) C:\windows\SysWOW64\cscript.exe
2013-12-11 08:04 - 2013-12-11 20:08 - 00121856 _____ (Microsoft Corporation) C:\windows\SysWOW64\wshom.ocx
2013-12-11 08:04 - 2013-10-04 03:16 - 00116736 ____C (Microsoft Corporation) C:\windows\system32\Drivers\drmk.sys
2013-12-11 08:04 - 2013-10-04 02:36 - 00230400 ____C (Microsoft Corporation) C:\windows\system32\Drivers\portcls.sys
2013-12-10 21:33 - 2013-12-10 21:33 - 09272200 ____C (Adobe Systems Incorporated) C:\windows\SysWOW64\FlashPlayerInstaller.exe

==================== One Month Modified Files and Folders =======

2013-12-22 22:37 - 2013-12-22 22:36 - 00022702 ____C C:\Users\max\Downloads\FRST.txt
2013-12-22 22:36 - 2013-12-22 22:36 - 00000000 ___DC C:\FRST
2013-12-22 22:35 - 2013-12-22 22:35 - 01928280 ____C (Farbar) C:\Users\max\Downloads\FRST64.exe
2013-12-22 22:34 - 2013-12-22 22:34 - 00000468 ____C C:\Users\max\Downloads\defogger_disable.log
2013-12-22 22:34 - 2013-12-22 22:34 - 00000000 ____C C:\Users\max\defogger_reenable
2013-12-22 22:34 - 2010-04-06 09:07 - 00000000 ___DC C:\Users\max
2013-12-22 22:33 - 2013-12-22 22:33 - 00050477 ____C C:\Users\max\Downloads\Defogger.exe
2013-12-22 22:33 - 2012-04-15 06:51 - 00000884 ____C C:\windows\Tasks\Adobe Flash Player Updater.job
2013-12-22 22:16 - 2010-02-10 00:33 - 00654400 ____C C:\windows\system32\perfh007.dat
2013-12-22 22:16 - 2010-02-10 00:33 - 00130240 ____C C:\windows\system32\perfc007.dat
2013-12-22 22:16 - 2009-07-14 06:13 - 01498742 ____C C:\windows\system32\PerfStringBackup.INI
2013-12-22 21:57 - 2011-07-23 15:05 - 00001104 ____C C:\windows\Tasks\GoogleUpdateTaskMachineUA.job
2013-12-22 21:30 - 2010-02-09 06:58 - 01709460 ____C C:\windows\WindowsUpdate.log
2013-12-22 20:57 - 2011-07-23 15:05 - 00001100 ____C C:\windows\Tasks\GoogleUpdateTaskMachineCore.job
2013-12-22 18:21 - 2013-09-28 09:15 - 00000000 ___DC C:\Users\max\AppData\Roaming\vlc
2013-12-22 16:16 - 2013-12-22 16:16 - 04379048 ____C (Piriform Ltd) C:\Users\max\Downloads\ccsetup407.exe
2013-12-22 10:13 - 2009-07-14 05:45 - 00013936 ___HC C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2013-12-22 10:13 - 2009-07-14 05:45 - 00013936 ___HC C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2013-12-22 10:06 - 2012-07-10 13:58 - 00004184 ____C C:\windows\System32\Tasks\avast! Emergency Update
2013-12-22 10:05 - 2013-12-22 10:05 - 00000000 __RDC C:\Users\max\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\CyberLink PowerDVD 8
2013-12-22 10:03 - 2009-07-14 06:08 - 00000006 ___HC C:\windows\Tasks\SA.DAT
2013-12-21 09:19 - 2012-04-26 06:39 - 00000000 ___DC C:\Program Files (x86)\Mozilla Maintenance Service
2013-12-20 14:18 - 2013-12-20 14:17 - 00000000 ___DC C:\Program Files (x86)\Mozilla Firefox
2013-12-19 22:08 - 2013-09-23 08:34 - 00000700 ____C C:\Users\max\Desktop\Film-Tips.txt
2013-12-18 21:22 - 2013-12-18 21:22 - 00000664 ____C C:\Users\max\Desktop\Filme_Michael_Caine.txt
2013-12-15 19:23 - 2013-08-01 21:03 - 00000000 ___DC C:\windows\system32\MRT
2013-12-15 19:22 - 2010-04-10 07:27 - 90708896 ____C (Microsoft Corporation) C:\windows\system32\MRT.exe
2013-12-15 16:52 - 2013-06-19 12:32 - 00000000 ___DC C:\Users\max\.gimp-2.8
2013-12-15 13:03 - 2013-12-15 13:03 - 00368343 ____C C:\Users\max\AppData\Local\recently-used.xbel
2013-12-14 08:53 - 2013-12-14 08:53 - 00000000 ___DC C:\Users\max\AppData\Roaming\AVAST Software
2013-12-13 21:11 - 2013-03-19 16:22 - 00205320 _____ C:\windows\system32\Drivers\aswVmm.sys
2013-12-13 21:11 - 2013-03-19 16:22 - 00065776 _____ C:\windows\system32\Drivers\aswRvrt.sys
2013-12-13 21:11 - 2012-02-26 13:20 - 00092544 _____ (AVAST Software) C:\windows\system32\Drivers\aswRdr2.sys
2013-12-13 21:11 - 2011-05-27 09:09 - 01032416 _____ (AVAST Software) C:\windows\system32\Drivers\aswSnx.sys
2013-12-13 21:11 - 2011-01-21 12:45 - 00334648 _____ (AVAST Software) C:\windows\system32\aswBoot.exe
2013-12-13 21:11 - 2011-01-21 12:45 - 00043152 ____C (AVAST Software) C:\windows\avastSS.scr
2013-12-13 21:11 - 2010-04-22 05:41 - 00409832 _____ (AVAST Software) C:\windows\system32\Drivers\aswSP.sys
2013-12-13 21:11 - 2010-04-22 05:41 - 00084328 _____ (AVAST Software) C:\windows\system32\Drivers\aswMonFlt.sys
2013-12-13 21:11 - 2010-04-22 05:41 - 00065264 _____ (AVAST Software) C:\windows\system32\Drivers\aswTdi.sys
2013-12-13 21:11 - 2010-04-22 05:41 - 00038984 _____ (AVAST Software) C:\windows\system32\Drivers\aswFsBlk.sys
2013-12-13 21:11 - 2010-04-22 05:41 - 00001982 ____C C:\Users\Public\Desktop\avast! Free Antivirus.lnk
2013-12-13 21:10 - 2013-12-13 21:10 - 00000000 ___DC C:\ProgramData\AVAST Software
2013-12-13 21:10 - 2010-04-22 05:41 - 00000000 ____C C:\windows\SysWOW64\config.nt
2013-12-12 08:12 - 2013-12-11 18:51 - 00000000 ___DC C:\Program Files (x86)\Mozilla Thunderbird
2013-12-12 08:01 - 2009-07-14 06:09 - 00000000 ____D C:\windows\System32\Tasks\WPD
2013-12-12 07:59 - 2009-07-14 05:45 - 00486968 ____C C:\windows\system32\FNTCACHE.DAT
2013-12-11 20:11 - 2013-12-11 20:11 - 14631424 _____ (Microsoft Corporation) C:\windows\system32\wmp.dll
2013-12-11 20:11 - 2013-12-11 20:11 - 12625920 _____ (Microsoft Corporation) C:\windows\system32\wmploc.DLL
2013-12-11 20:11 - 2013-12-11 20:11 - 12625408 _____ (Microsoft Corporation) C:\windows\SysWOW64\wmploc.DLL
2013-12-11 20:11 - 2013-12-11 20:11 - 11410432 _____ (Microsoft Corporation) C:\windows\SysWOW64\wmp.dll
2013-12-11 20:10 - 2013-12-11 08:04 - 03155968 _____ (Microsoft Corporation) C:\windows\system32\win32k.sys
2013-12-11 20:10 - 2013-12-11 08:04 - 00465920 _____ (Microsoft Corporation) C:\windows\system32\WMPhoto.dll
2013-12-11 20:10 - 2013-12-11 08:04 - 00417792 _____ (Microsoft Corporation) C:\windows\SysWOW64\WMPhoto.dll
2013-12-11 20:10 - 2013-12-11 08:04 - 00335360 _____ (Microsoft Corporation) C:\windows\system32\msieftp.dll
2013-12-11 20:10 - 2013-12-11 08:04 - 00301568 _____ (Microsoft Corporation) C:\windows\SysWOW64\msieftp.dll
2013-12-11 20:10 - 2010-04-06 09:15 - 00000000 ___DC C:\ProgramData\Microsoft Help
2013-12-11 20:09 - 2013-12-11 20:09 - 23183360 _____ (Microsoft Corporation) C:\windows\system32\mshtml.dll
2013-12-11 20:09 - 2013-12-11 20:09 - 17112576 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtml.dll
2013-12-11 20:09 - 2013-12-11 20:09 - 12996608 _____ (Microsoft Corporation) C:\windows\system32\ieframe.dll
2013-12-11 20:09 - 2013-12-11 20:09 - 11221504 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieframe.dll
2013-12-11 20:09 - 2013-12-11 20:09 - 05769216 _____ (Microsoft Corporation) C:\windows\system32\jscript9.dll
2013-12-11 20:09 - 2013-12-11 20:09 - 04243968 _____ (Microsoft Corporation) C:\windows\SysWOW64\jscript9.dll
2013-12-11 20:09 - 2013-12-11 20:09 - 02764288 _____ (Microsoft Corporation) C:\windows\system32\iertutil.dll
2013-12-11 20:09 - 2013-12-11 20:09 - 02724864 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtml.tlb
2013-12-11 20:09 - 2013-12-11 20:09 - 02724864 _____ (Microsoft Corporation) C:\windows\system32\mshtml.tlb
2013-12-11 20:09 - 2013-12-11 20:09 - 02334208 _____ (Microsoft Corporation) C:\windows\system32\wininet.dll
2013-12-11 20:09 - 2013-12-11 20:09 - 02166784 _____ (Microsoft Corporation) C:\windows\SysWOW64\iertutil.dll
2013-12-11 20:09 - 2013-12-11 20:09 - 01995264 _____ (Microsoft Corporation) C:\windows\system32\inetcpl.cpl
2013-12-11 20:09 - 2013-12-11 20:09 - 01928192 _____ (Microsoft Corporation) C:\windows\SysWOW64\inetcpl.cpl
2013-12-11 20:09 - 2013-12-11 20:09 - 01820160 _____ (Microsoft Corporation) C:\windows\SysWOW64\wininet.dll
2013-12-11 20:09 - 2013-12-11 20:09 - 01395200 _____ (Microsoft Corporation) C:\windows\system32\urlmon.dll
2013-12-11 20:09 - 2013-12-11 20:09 - 01157632 _____ (Microsoft Corporation) C:\windows\SysWOW64\urlmon.dll
2013-12-11 20:09 - 2013-12-11 20:09 - 00817664 _____ (Microsoft Corporation) C:\windows\system32\ieapfltr.dll
2013-12-11 20:09 - 2013-12-11 20:09 - 00708608 _____ (Microsoft Corporation) C:\windows\system32\jscript9diag.dll
2013-12-11 20:09 - 2013-12-11 20:09 - 00703488 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieapfltr.dll
2013-12-11 20:09 - 2013-12-11 20:09 - 00574976 _____ (Microsoft Corporation) C:\windows\system32\ieui.dll
2013-12-11 20:09 - 2013-12-11 20:09 - 00553472 _____ (Microsoft Corporation) C:\windows\SysWOW64\jscript9diag.dll
2013-12-11 20:09 - 2013-12-11 20:09 - 00440832 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieui.dll
2013-12-11 20:09 - 2013-12-11 20:09 - 00218624 _____ (Microsoft Corporation) C:\windows\system32\ie4uinit.exe
2013-12-11 20:09 - 2013-12-11 20:09 - 00139264 _____ (Microsoft Corporation) C:\windows\system32\ieUnatt.exe
2013-12-11 20:09 - 2013-12-11 20:09 - 00111616 _____ (Microsoft Corporation) C:\windows\system32\ieetwcollector.exe
2013-12-11 20:09 - 2013-12-11 20:09 - 00066048 _____ (Microsoft Corporation) C:\windows\system32\iesetup.dll
2013-12-11 20:09 - 2013-12-11 20:09 - 00053760 _____ (Microsoft Corporation) C:\windows\system32\jsproxy.dll
2013-12-11 20:09 - 2013-12-11 20:09 - 00048640 _____ (Microsoft Corporation) C:\windows\system32\ieetwproxystub.dll
2013-12-11 20:09 - 2013-12-11 20:09 - 00043008 _____ (Microsoft Corporation) C:\windows\SysWOW64\jsproxy.dll
2013-12-11 20:09 - 2013-12-11 20:09 - 00033792 _____ (Microsoft Corporation) C:\windows\system32\iernonce.dll
2013-12-11 20:09 - 2013-12-11 20:09 - 00004096 _____ (Microsoft Corporation) C:\windows\system32\ieetwcollectorres.dll
2013-12-11 20:09 - 2013-12-11 08:04 - 00159232 _____ (Microsoft Corporation) C:\windows\SysWOW64\imagehlp.dll
2013-12-11 20:09 - 2013-12-11 08:04 - 00081408 _____ (Microsoft Corporation) C:\windows\system32\imagehlp.dll
2013-12-11 20:09 - 2013-12-11 08:04 - 00002048 _____ (Microsoft Corporation) C:\windows\SysWOW64\tzres.dll
2013-12-11 20:09 - 2013-12-11 08:04 - 00002048 _____ (Microsoft Corporation) C:\windows\system32\tzres.dll
2013-12-11 20:08 - 2013-12-11 08:04 - 00202752 _____ (Microsoft Corporation) C:\windows\system32\scrrun.dll
2013-12-11 20:08 - 2013-12-11 08:04 - 00168960 _____ (Microsoft Corporation) C:\windows\system32\wscript.exe
2013-12-11 20:08 - 2013-12-11 08:04 - 00163840 _____ (Microsoft Corporation) C:\windows\SysWOW64\scrrun.dll
2013-12-11 20:08 - 2013-12-11 08:04 - 00156160 _____ (Microsoft Corporation) C:\windows\system32\cscript.exe
2013-12-11 20:08 - 2013-12-11 08:04 - 00150016 _____ (Microsoft Corporation) C:\windows\system32\wshom.ocx
2013-12-11 20:08 - 2013-12-11 08:04 - 00141824 _____ (Microsoft Corporation) C:\windows\SysWOW64\wscript.exe
2013-12-11 20:08 - 2013-12-11 08:04 - 00126976 _____ (Microsoft Corporation) C:\windows\SysWOW64\cscript.exe
2013-12-11 20:08 - 2013-12-11 08:04 - 00121856 _____ (Microsoft Corporation) C:\windows\SysWOW64\wshom.ocx
2013-12-11 10:00 - 2013-10-25 05:43 - 00001716 ____C C:\Users\max\Desktop\Oberstdorf-Reisetips.txt
2013-12-11 08:21 - 2013-12-11 08:21 - 00000000 ___DC C:\Users\max\Documents\PC Speed Maximizer
2013-12-11 08:16 - 2013-12-11 08:16 - 00002768 ____C C:\windows\System32\Tasks\CCleanerSkipUAC
2013-12-11 08:16 - 2013-12-11 08:16 - 00000827 ____C C:\Users\Public\Desktop\CCleaner.lnk
2013-12-11 08:16 - 2013-12-11 08:16 - 00000000 ___DC C:\Program Files\CCleaner
2013-12-11 08:15 - 2013-12-11 08:15 - 00000000 ___DC C:\ProgramData\Websteroids
2013-12-11 08:15 - 2013-12-11 08:15 - 00000000 ___DC C:\ProgramData\Updater
2013-12-11 08:15 - 2013-12-11 08:15 - 00000000 ___DC C:\ProgramData\RHelpers
2013-12-11 08:13 - 2013-12-11 08:13 - 01080504 ____C (Conduit) C:\Users\max\Downloads\CCleaner_TSV426SC.exe
2013-12-10 21:33 - 2013-12-10 21:33 - 09272200 ____C (Adobe Systems Incorporated) C:\windows\SysWOW64\FlashPlayerInstaller.exe
2013-12-10 21:33 - 2012-04-15 06:51 - 00692616 ____C (Adobe Systems Incorporated) C:\windows\SysWOW64\FlashPlayerApp.exe
2013-12-10 21:33 - 2012-04-15 06:51 - 00003822 _____ C:\windows\System32\Tasks\Adobe Flash Player Updater
2013-12-10 21:33 - 2011-10-07 17:41 - 00071048 ____C (Adobe Systems Incorporated) C:\windows\SysWOW64\FlashPlayerCPLApp.cpl
2013-12-09 20:02 - 2013-10-22 08:13 - 00002831 ____C C:\Users\max\Desktop\Fahrplan-Romantische_Schiene_EM_Noerdlingen.txt
2013-12-02 20:52 - 2011-07-23 15:05 - 00004100 _____ C:\windows\System32\Tasks\GoogleUpdateTaskMachineUA
2013-12-02 20:52 - 2011-07-23 15:05 - 00003848 _____ C:\windows\System32\Tasks\GoogleUpdateTaskMachineCore
2013-11-23 18:28 - 2009-07-14 04:20 - 00000000 ____D C:\windows\rescache
2013-11-23 09:13 - 2013-03-16 19:51 - 00000000 ___DC C:\Users\max\Documents\Movie Studio Platinum 12.0 Projekte
2013-11-22 07:58 - 2010-04-14 07:51 - 00000000 ___DC C:\windows\Minidump
2013-11-22 07:58 - 2009-08-02 03:27 - 00000000 ___DC C:\windows\Panther

==================== Bamital & volsnap Check =================

C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit


LastRegBack: 2013-12-10 21:49

==================== End Of Log ============================
         
--- --- ---

--- --- ---

--- --- ---

 

Themen zu immer wieder neue Setup.exe in Temp-Ordner
adblock, adware.agent, antivirus, ccsetup, defender, device driver, flash player, harddisk, installation, internet explorer, internet explorer 10, newtab, plug-in, programm, pup.optional.babylon.a, pup.optional.delta.a, pup.optional.iminent.a, pup.optional.installcore.a, pup.optional.mixidjtoolbar.a, pup.optional.opencandy, pup.optional.pricepeep.a, pup.optional.safemonitor.a, pup.optional.softonic.a, pup.optional.speedanalysis2.a, pup.optional.startpage, pup.optional.wajam.a, refresh, richtlinie, security, software, wajam, windows




Ähnliche Themen: immer wieder neue Setup.exe in Temp-Ordner


  1. Ordner Boost_interprocess immer wieder da !
    Plagegeister aller Art und deren Bekämpfung - 21.10.2013 (21)
  2. Immer wiederkehrender Virus und immer neuer Name auch im Temp Ordner
    Plagegeister aller Art und deren Bekämpfung - 16.07.2012 (5)
  3. Temp Ordner immer Schreibgeschützt. Bin ich verseucht?
    Log-Analyse und Auswertung - 09.08.2011 (8)
  4. Viren erscheint nach Neustart immer wieder (setup.....)
    Plagegeister aller Art und deren Bekämpfung - 21.05.2011 (41)
  5. Es erstellt sich immer ein Ordner und er kommt immer wieder
    Plagegeister aller Art und deren Bekämpfung - 14.04.2011 (1)
  6. Setup.exe generiert sich immer in den selben Ordner zurück.
    Plagegeister aller Art und deren Bekämpfung - 22.07.2010 (5)
  7. Unregelmäßigkeiten auf Bankseite und immer wieder svchost.exe im Temp Ordner
    Plagegeister aller Art und deren Bekämpfung - 01.07.2010 (1)
  8. AntiVir Guard inaktiv, lässt sich nicht deinstallieren, startet immer wieder Setup
    Antiviren-, Firewall- und andere Schutzprogramme - 10.06.2010 (39)
  9. Automatisch neue Ordner in Windows/Temp nach Trojan/Virusbefall
    Plagegeister aller Art und deren Bekämpfung - 27.05.2010 (2)
  10. svchost.exe erstellt sich immer wieder neu im TEMP Ordner
    Plagegeister aller Art und deren Bekämpfung - 18.01.2010 (1)
  11. unruy.c / Koobface.K / Trojaner generiert sich immer wieder im Temp
    Plagegeister aller Art und deren Bekämpfung - 08.11.2009 (7)
  12. Win XP Setup wird immer wieder neu gestartet..
    Alles rund um Windows - 04.05.2009 (7)
  13. TR/Agent.iob immer wieder im temp Ordner - wie krieg ich den weg ?
    Plagegeister aller Art und deren Bekämpfung - 12.11.2008 (1)
  14. Ständig neue Datei nach dem löschen in temp Ordner
    Log-Analyse und Auswertung - 15.08.2008 (22)
  15. immer wieder Downloader in C:\\Windows\temp files
    Plagegeister aller Art und deren Bekämpfung - 02.10.2007 (12)
  16. Trojaner generiert sich immer wieder neu im windows/temp ordner
    Log-Analyse und Auswertung - 21.07.2007 (8)
  17. Ordner und exe kommen immer wieder
    Log-Analyse und Auswertung - 05.12.2006 (3)

Zum Thema immer wieder neue Setup.exe in Temp-Ordner - Hallo zusammen, Ich habe seit ein paar Tagen immer wieder eine merkwürdige Setup.exe in meinem Temp-Ordner. Aus dem Nichts heraus kommt dann jedesmal die Abfrage, ob ich die Installation zulassen - immer wieder neue Setup.exe in Temp-Ordner...
Archiv
Du betrachtest: immer wieder neue Setup.exe in Temp-Ordner auf Trojaner-Board

Search Engine Optimization by vBSEO ©2011, Crawlability, Inc.